Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2021-1675 — Exploit for CVE-2021-1675 (PrintNightmare) enabling local and remote SYSTEM-level privilege escalation on Windows via the Print Spooler service. Includes Ladon module integration. | Kitploit
Tools/GitHubGitHub/k8gege/cve-2021-1675
Privilege EscalationExploit FrameworksVulnerability AnalysisExploitationPenetration Testing
GitHubk8gege/cve-2021-1675

cve-2021-1675

Exploit for CVE-2021-1675 (PrintNightmare) enabling local and remote SYSTEM-level privilege escalation on Windows via the Print Spooler service. Includes Ladon module integration.

View Repository
153805 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

〖EXP〗Ladon Printer Vulnerability Privilege Escalation CVE-2021-1675 Reproduction

http://k8gege.org/p/CVE-2021-1675.html

Overview

On June 9, Microsoft released the June security update patch, fixing 50 security vulnerabilities, including a Windows Print Spooler privilege escalation vulnerability, CVE ID: CVE-2021-1675. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges on a domain controller, thereby gaining control of the entire domain. It is recommended that affected users update the patch promptly for protection, conduct asset self-inspection and prevention to avoid hacker attacks.

Vulnerability Description

Print Spooler is a service in Windows systems used to manage print-related tasks.

Under suitable conditions in a domain environment, without any user interaction, an unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code with SYSTEM privileges on a domain controller, thereby gaining control of the entire domain.

Affected Range

root@kitploit:~
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows RT 8.1
Windows 8.1 for x64-based systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
Windows Server, version 20H2 (Server Core Installation)
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server, version 2004 (Server Core installation)
Windows 10 Version 2004 for x64-based Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 21H1 for 32-bit Systems
Windows 10 Version 21H1 for ARM64-based Systems
Windows 10 Version 21H1 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems

Version

Ladon >= 8.6

Usage

Ladon CVE-2021-1675 DllPath

Examples

Ladon CVE-2021-1675 c:\evil.dll Ladon PrintNightmare c:\evil.dll

Local Privilege Escalation

Win2019 image

Win2016 image

Win10 image

Remote Privilege Escalation

Win2016 image

Related POC

C++, Python, C#, PowerShell https://github.com/afwu/PrintNightmare https://github.com/cube0x0/CVE-2021-1675 https://github.com/calebstewart/CVE-2021-1675

Download

LadonGo (ALL OS)

https://github.com/k8gege/LadonGo/releases

Ladon (Windows & Cobalt Strike)

Historic Versions: https://github.com/k8gege/Ladon/releases Version 7.0: http://k8gege.org/Download Version 8.6: K8小密圈

Download Tool